US6032260AExpiredUtility

Method for issuing a new authenticated electronic ticket based on an expired authenticated ticket and distributed server architecture for using same

Assignee: NCR CORPPriority: Nov 13, 1997Filed: Nov 13, 1997Granted: Feb 29, 2000
Est. expiryNov 13, 2017(expired)· nominal 20-yr term from priority
H04L 9/3239G06F 21/335H04L 9/3247H04L 63/0846H04L 63/123H04L 2209/56
86
PatentIndex Score
187
Cited by
6
References
17
Claims

Abstract

A computer program memory stores computer instructions for securing data transmitted over a system, such as the Internet, enabling a user to be authenticated and authorized for a requested operation. An "eticket" architecture (including identification information) is generated by an authentication server. The information in the eticket is hashed using, for example, a Message Digest Protocol, and a hash number is generated. The hash number is then encrypted using a private key, and the identification information in the eticket and the encrypted hash number are concatenated to generate a completed "eticket" architecture. The "eticket" may then be transmitted over the Internet (i.e., a non-secure environment) from server to server without having the information in the "eticket" altered, and without having to "reauthenticate" the user at each server.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method for updating an electronic ticket issued on a distributed computer system and server architecture, the electronic ticket used for verifying user authorization to provide secure data communication over the distributed computer system and server architecture, comprising the steps of: providing a data packet having essentially the same information as the electronic ticket and based on at least the authorization information;   producing a signature by hashing at least the authorization information;   encrypting at least the signature to prevent unauthorized alteration of the information in the data packet;   concatenating the information in the data packet with the encrypted signature to produce another electronic ticket;   issuing the another electronic ticket when the electronic ticket expires; and   transmitting the another electronic ticket over the distributed computer system and server architecture in a non-secure environment.   
     
     
       2. The method for updating an electronic ticket according to claim 1, further comprising the steps of: authenticating a user based on authentication information to generate the another electronic ticket including the authorization information; and   authorizing the user to access system resources upon validating the integrity of the information in the another electronic ticket transmitted in the non-secured environment.   
     
     
       3. The method for updating an electronic ticket according to claim 1, further comprising the steps of: rehashing the information in the another electronic ticket; and   decrypting the information in the another electronic ticket using a public key.   
     
     
       4. The method for updating an electronic ticket according to claim 1, wherein the encrypting step uses a private key to encrypt the signature. 
     
     
       5. The method for updating an electronic ticket according to claim 1, wherein the producing step uses MD5 protocol to hash the authorization information. 
     
     
       6. The method for updating an electronic ticket according to claim 1, wherein the information in the electronic ticket includes issuer server name, client IP address, expiration date and time, and user name. 
     
     
       7. The method for updating an electronic ticket according to claim 6, wherein the electronic ticket expires at the expiration date and time. 
     
     
       8. The method for updating an electronic ticket according to claim 6, wherein the electronic ticket expires after the expiration date and time when a user request is completed after the expiration date and time of the electronic ticket. 
     
     
       9. The method for updating an electronic ticket according to claim 6, wherein the electronic ticket expires before the expiration date and time when a user request is completed before the expiration date and time of the electronic ticket. 
     
     
       10. The method for updating an electronic ticket according to claim 1, wherein the electronic ticket expires when a user request is not made within a pre-specified time period. 
     
     
       11. A method for updating an electronic ticket issued on a distributed computer system and server architecture, the electronic ticket used for verifying user authorization to provide secure data communication over the distributed computer system and server architecture, comprising the steps of: providing a data packet based on at least the authorization information;   hashing the information in the data packet and producing a hash number;   concatenating the information in the data packet with the hash number to produce another electronic ticket; and   issuing the another electronic ticket after the electronic ticket expires.   
     
     
       12. A distributed computer system and server architecture for updating an electronic ticket issued on the distributed computer system and server architecture, the electronic ticket used for verifying user authorization to provide secure data communication over the distributed computer system and server architecture, comprising: at least one storage device for storing data;   at least one user computer transmitting the user authorization information and a user request; and   at least one server, connectable to the at least one storage device and the at least one user computer, issuing another electronic ticket when the electronic ticket expires, wherein the another electronic ticket is produced by: providing a data packet having essentially the same information as the electronic ticket based on at least the authorization information,   producing a signature by hashing at least the authorization information,   encrypting at least the signature to prevent unauthorized alteration of the information the data packet,   concatenating the information in the data packet with the encrypted signature to produce the another electronic ticket.     
     
     
       13. The distributed computer system and server architecture according to claim 12, further comprising at least another server authorizing the user to access system resources upon validating the integrity of the information in the another electronic ticket. 
     
     
       14. The distributed computer system and server architecture according to claim 12, wherein the at least one server is an authentication server authenticating the user based on authentication information to issue and transmit the another electronic ticket. 
     
     
       15. A distributed computer system and server architecture for updating an electronic ticket issued on the distributed computer system and server architecture, the electronic ticket used for verifying user authorization to provide secure data communication over the distributed computer system and server architecture, comprising: at least one storage device for storing data;   at least one user computer transmitting the user authorization information and a user request; and   at least one server, connectable to the at least one storage device and the at least one user computer, issuing another electronic ticket after the electronic ticket expires, wherein the another electronic ticket is produced by: providing a data packet based on at least the authorization information,   hashing the information in the data packet and producing a hash number, and   concatenating the information in the data packet with the hash number to produce the another electronic ticket.     
     
     
       16. The distributed computer system of claim 11, wherein said another electronic ticket is issued at the time when the electronic ticket expires. 
     
     
       17. The distributed computer system of claim 15, wherein said another electronic ticket is issued at the time when the electronic ticket expires.

Join the waitlist — get patent alerts

Track US6032260A — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.